PERANCANGAN DAN IMPLEMENTASI SISTEM DETEKSI DAN MANAJEMEN INSIDEN KEAMANAN SIBER BERBASIS LOG AUTENTIKASI SSO PADA PT. XYZ

dc.contributor.advisorHaikal, Antoni
dc.contributor.authorSimanjuntak, Vincentius
dc.date.accessioned2026-08-24T07:59:35Z
dc.date.issued2026-09-09
dc.description.abstractThe advancement of information technology has driven the widespread adoption of Single Sign-On (SSO) as a centralized authentication solution, making it a prime target for attacks such as brute force and credential stuffing. This study proposes the design and implementation of a cybersecurity incident detection and management system based on Keycloak SSO authentication log analysis. The system integrates four main components: Keycloak as the SSO provider, Redis for alert deduplication and temporary storage, TheHive as the incident management platform, and n8n for workflow automation. Threat detection is performed by a Python worker that continuously reads Keycloak LOGIN_ERROR logs and compares them against defined security rules—brute force and credential stuffing detection. A deduplication mechanism using Redis prevents duplicate incident tickets from being created in TheHive. Experimental testing with simultaneous attack injection from two IP addresses across eight simulation scenarios showed that the system achieved 100% detection accuracy for both attack types. The deduplication mechanism successfully ensured only one unique incident case was created per attacker entity per day. The average end-to-end processing time from alert detection to case creation in TheHive was 2.937 seconds. These results demonstrate that the proposed architecture effectively automates security monitoring, alert deduplication, and incident ticket creation in an efficient and structured manner.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa_Keamanan_Siber
dc.identifier.nidnNIDN8942560023
dc.identifier.nimNIM4332211002
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/5862
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectSingle Sign-On
dc.subjectKeycloak
dc.subjectbrute force
dc.subjectcredential stuffing
dc.subjectlog analysis
dc.subjectRedis
dc.subjectTheHive
dc.subjectincident
dc.subjectmanagement
dc.subjectdeduplication
dc.titlePERANCANGAN DAN IMPLEMENTASI SISTEM DETEKSI DAN MANAJEMEN INSIDEN KEAMANAN SIBER BERBASIS LOG AUTENTIKASI SSO PADA PT. XYZ
dc.title.alternativeDESIGN AND IMPLEMENTATION OF A LOG-BASED CYBERSECURITY INCIDENT DETECTION AND MANAGEMENT SYSTEM FOR SSO AUTHENTICATION AT PT. XYZ
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
4332211002_Artikel.pdf
Size:
4.25 MB
Format:
Adobe Portable Document Format
Description:
Full Page Artikel
Loading...
Thumbnail Image
Name:
Lembar_Pengesahan.pdf
Size:
123.44 KB
Format:
Adobe Portable Document Format
Description:
Lembar Pengesahan
Loading...
Thumbnail Image
Name:
Borang_Publikasi.pdf
Size:
168.26 KB
Format:
Adobe Portable Document Format
Description:
Borang Publikasi

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: